By vendor

Aqara vulnerabilities

Known CVEs affecting Aqara products, prioritized by severity, with SEC.co remediation and detection guidance.

5 published vulnerabilities

  • CVE-2026-50085HIGH 8.6

    The Aqara Board service at op-test.aqara.com has a critical flaw where it accepts any MQTT command without verifying the sender's identity, then passes these commands directly to the platform's message broker. An attacker on the internet can send malicious commands that affect Aqara devices without needing credentials. While this vulnerability alone allows partial device compromise, it becomes far more dangerous when combined with three related vulnerabilities that enable complete device takeover.

  • CVE-2026-50087HIGH 8.2

    Aqara's IAM/SSO gateway (gw-builder.aqara.com) allows a web attacker to make unauthorized requests on behalf of an authenticated user visiting a malicious site. The gateway's cross-origin policy is too permissive, enabling an attacker to steal sensitive user data or make unwanted changes to account settings without the user's knowledge. An attacker cannot directly access the system—they rely on tricking a user into clicking a link or visiting a crafted webpage while logged into the Aqara gateway.

  • CVE-2026-50088HIGH 8.2

    The Aqara Developer Portal and its associated test environments allow web pages from untrusted domains to make authenticated requests on behalf of users. This cross-origin vulnerability means an attacker could craft a malicious webpage that, when visited by a developer logged into Aqara's portal, silently retrieves sensitive information or makes unwanted changes. The vulnerability requires user interaction (visiting a malicious site) but can expose confidential data and modify account settings.

  • CVE-2026-50082MEDIUM 6.5

    Aqara's Cloud Developer Portal contained a flaw that allowed attackers to obtain developer tokens for any email address without proper authentication. An attacker could request a token using any email (including one they don't control) and the system would issue valid credentials. While this vulnerability alone provides limited access (confidentiality and integrity impact), it becomes dangerous when chained with three related vulnerabilities (CVE-2026-50083, CVE-2026-50084, CVE-2026-50085), potentially enabling complete device takeover for affected Aqara IoT devices.

  • CVE-2026-50089MEDIUM 6.1

    Aqara's IAM/SSO Gateway (gw-builder.aqara.com) contains an open redirect flaw that allows attackers to craft malicious links appearing to direct users to the legitimate Aqara domain, but actually redirecting them to attacker-controlled sites. This is a classic phishing vector: a user trusts the initial Aqara URL, clicks it, and lands on a fraudulent login page or malware distribution point. The vulnerability requires user interaction (a click) and affects the confidentiality and integrity of user sessions, making it a medium-severity network-based threat.